Prerequisites to update firmware remotely using iLO
About this task
Before starting a remote firmware update using HPE iLO, ensure that the following requirements are met:
Procedure
- Verify that you have infrastructure administrator or server administrator privileges.
- Verify that you can access the Smart Update Manager (SUM) UI.
- Verify that one or more servers are added to the system and are in a reachable state.
- Ensure that a firmware baseline is already added to the system. When using a custom Service pack for HPE ProLiant (SPP), include all required firmware variants and components. An SPP containing only Smart Firmware components of RPM type is not supported.
-
Verify that a supported version of Integrated Smart Update Tools (iSUT) is
installed, running, and configured on each target server.
- Considerations for modes in iSUT:
- Do not configure iSUT in OnDemand or AutoStage mode.
- In iSUT AutoDeployReboot and iSUT AutoDeploy modes, iSUT automatically restarts the server when a reboot is required.
- Supported iSUT versions:
- Gen12 servers with iLO 7 - Version 6.0.0 or later
- Gen10, Gen10 Plus, Gen11, and Gen12 servers with iLO 6 - Version 2.9.3 or later
- VMware ESXi servers - Version 4.1.0 or later
- Considerations for modes in iSUT:
-
Enable iLO queued updates by using the command
sut -set enableiloqueuedupdates=true.
Verify that Agentless Management Service (AMS) is installed and running on each server. In HPE iLO, select and confirm that AMS is running and the installed version is supported for the server.
- In HPE iLO, verify that the Agentless Management Service (AMS) is installed and running on each server. Select Firmware & OS Sofwar and select the Software tab to confirm AMS is running.
-
Optional. Configure communication between iSUT and iLO over the virtual NIC
(vNIC) for Gen12 servers with iLO 7:
-
create the iSUT application account using the command
sut appaccount create -u <ilo_username> -p <ilo_password>. -
Configure AMS communication over the vNIC using the command
amscli appaccount create -u <ilo_username> -p <ilo_password>.
-
create the iSUT application account using the command
-
Optional. If any of the following iLO security settings are enabled, follow the
below steps:
- Require Host Authentication
- High Security
- FIPS
- CNSA
- Optional. For HPE ProLiant Gen12 servers with iLO 7, firmware updates are not supported when CNSA security mode is enabled. Switch the security mode to FIPS or Production (Standard).
-
Configure iLO credentials in iSUT using an iLO account with both
Login and Configure iLO Settings privileges. Use the
command
sut -set ilousername=<username> ilopassword=<password>.
For more information, see the iSUT documentation here: https://hpe.com/support/integratedsmartupdatetools-quicklinks.
-
Verify readiness of each target server in HPE iLO: